News & Commentary

Content tagged with Compliance posted in October 2008
FTC Pushes Back 'Red Flag' Deadline
Quick Hits  |  10/24/2008  | 
Companies have another six months to develop identity theft prevention programs
Tech Insight: Digital Forensics & Incident Response Go Live
News  |  10/24/2008  | 
New tools, methods emerge for leveraging forensic data and memory analysis in the wake of an attack
Microsoft Blue Hat: Researcher Demos No-Hack Attack
News  |  10/21/2008  | 
Wealth of available online data on individuals, businesses can be used in targeted attacks
Making ID & Access Management More Accessible
News  |  10/20/2008  | 
New tools automate, simplify the access certification process
When Dates Attack
Quick Hits  |  10/20/2008  | 
Dating 'alert' sites allow women to put an 'ex' on trial without rebuttal
SSL VPN Secures iPhone, Extranet Sessions
News  |  10/17/2008  | 
Silicon Valley startup gets more mileage out of its VPN
Inspector General Report: Two IRS Applications Leave Taxpayer Data at Risk
News  |  10/16/2008  | 
IRS knowingly rolled out systems that contained security vulnerabilities
Users Know Security Policy & Break It Anyway, Study Says
Quick Hits  |  10/15/2008  | 
Many users feel they need to work around company security rules, according to RSA research
Stolen eBay Account Booty Found
Quick Hits  |  10/13/2008  | 
Over 5,000 pilfered accounts - mostly from newly registered, less active eBay user accounts
World Bank Hacked, Sensitive Data Exposed
News  |  10/10/2008  | 
Hacked Web servers, a stolen administrative account, and lot of unanswered questions
The Six Most Promising Security Startups of 2008
News  |  10/10/2008  | 
Judges unveil six finalists in the annual Global Security Challenge
Free Tool Hacks Banking, Webmail, and Social Networking Sessions
News  |  10/6/2008  | 
Man-in-the-middle attack tool automates hacks for non-Web security experts
Deutsche Telekom & T-Mobile Confirm Theft of Personal Data on 17M Customers
News  |  10/6/2008  | 
Data stolen in 2006 is already in use by criminals, reports say
'Super Users' Could Threaten Database Security, Study Says
Quick Hits  |  10/1/2008  | 
Survey by Independent Oracle Users Group says most database administrators haven't implemented proper defenses
IBM Takes On Retail Crime
News  |  10/1/2008  | 
New package of integrated products and services offered as alternative to current mishmash of in-store security technology


WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17229
PUBLISHED: 2018-09-19
Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
CVE-2018-17230
PUBLISHED: 2018-09-19
Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
CVE-2018-17231
PUBLISHED: 2018-09-19
** DISPUTED ** Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers an "index out of range" condition. NOTE: this issue is disputed by multiple third par...
CVE-2018-17228
PUBLISHED: 2018-09-19
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
CVE-2018-8889
PUBLISHED: 2018-09-19
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.